<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MAB &amp;amp; Dot1x with NPS - new mac address is seen? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724516#M901867</link>
    <description>&lt;P&gt;All port have Cisco 6921 phones with Dell Pc's behind them.&lt;/P&gt;
&lt;P&gt;I think I may have found the culprit.......SCCM wake up proxy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was seeing mac addresses of different pc's switching to different ports even though those pc's were not physically doing it. So I started to think "mac flap" which finally lead me to this post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/switching/mac-address-flapping-and-sccm-wake-up-proxy/td-p/2240432" target="_self"&gt;https://community.cisco.com/t5/switching/mac-address-flapping-and-sccm-wake-up-proxy/td-p/2240432&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So, into SCCM and disabled M$ version of wake on lan called "Wake up proxy" and since that, all appears ok.&lt;/P&gt;
&lt;P&gt;Early days yet but it's looking promising. Microsoft strikes again!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Oct 2018 18:57:11 GMT</pubDate>
    <dc:creator>louis0001</dc:creator>
    <dc:date>2018-10-12T18:57:11Z</dc:date>
    <item>
      <title>MAB &amp; Dot1x with NPS - new mac address is seen?</title>
      <link>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724183#M901864</link>
      <description>&lt;P&gt;I've got a really strange issue going on with MAB &amp;amp; dot1x with ports going into security violation every now and again claiming a new mac address is seen. Problem is, I know for sure that the clients aren't being changed on the ports so I'm not sure where the new mac address is coming from?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The ports are using:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;MAB for Cisco phones&lt;BR /&gt;Dot1x for clients behind the phones.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;A typical error is:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV id="msg"&gt;
&lt;P&gt;%AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface GigabitEthernet0/8, new MAC address (90b1.1c68.3e5e) is seen.AuditSessionID 0A011CE300000DDBB3DEFE36&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Interface config:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/8&lt;BR /&gt;&amp;nbsp;description PORT 916&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;switchport voice vlan 250&lt;BR /&gt;&amp;nbsp;authentication control-direction in&lt;BR /&gt;&amp;nbsp;authentication event fail retry 0 action authorize vlan 100&lt;BR /&gt;&amp;nbsp;authentication event server dead action authorize vlan 200&lt;BR /&gt;&amp;nbsp;authentication event no-response action authorize vlan 100&lt;BR /&gt;&amp;nbsp;authentication event server alive action reinitialize&lt;BR /&gt;&amp;nbsp;authentication host-mode multi-domain&lt;BR /&gt;&amp;nbsp;authentication order mab dot1x&lt;BR /&gt;&amp;nbsp;authentication priority dot1x mab&lt;BR /&gt;&amp;nbsp;authentication port-control auto&lt;BR /&gt;&amp;nbsp;authentication periodic&lt;BR /&gt;&amp;nbsp;authentication timer reauthenticate server&lt;BR /&gt;&amp;nbsp;mab&lt;BR /&gt;&amp;nbsp;dot1x pae authenticator&lt;BR /&gt;&amp;nbsp;dot1x timeout tx-period 10&lt;BR /&gt;&amp;nbsp;spanning-tree portfast&lt;BR /&gt;&amp;nbsp;spanning-tree bpduguard enable&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are no timeouts on the aaa servers and NPS is configured to use in following order:&lt;/P&gt;
&lt;P&gt;1. Dot1x for windows group domain computers&lt;BR /&gt;2. MAB for Cisco phones for windows group Cisco Phones (not member of domain computers)&lt;/P&gt;
&lt;P&gt;We're testing with a 3560 (old but with 15.2) and a 2960s-psl (using 15.2) and we're getting the same issue so I'm convinced it's some sort of mis config rather than the switches/firmware&lt;/P&gt;
&lt;P&gt;I'm a little lost to what's occurring here so any pointers would be appreciated.&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724183#M901864</guid>
      <dc:creator>louis0001</dc:creator>
      <dc:date>2020-02-21T16:20:48Z</dc:date>
    </item>
    <item>
      <title>Re: MAB &amp; Dot1x with NPS - new mac address is seen?</title>
      <link>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724224#M901865</link>
      <description>&lt;P&gt;Even more strange is over the last 24 hours I've seen the new mac address seen as:&lt;/P&gt;
&lt;P&gt;90b1.1c64.cdb5&lt;BR /&gt;90b1.1c64.3e5e&lt;/P&gt;
&lt;P&gt;90b1.1c64.935d&lt;/P&gt;
&lt;P&gt;and the client hasn't been changed. the first 2 are jumping between g0/8 &amp;amp; G0/9?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 09:29:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724224#M901865</guid>
      <dc:creator>louis0001</dc:creator>
      <dc:date>2018-10-12T09:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: MAB &amp; Dot1x with NPS - new mac address is seen?</title>
      <link>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724230#M901866</link>
      <description>&lt;P&gt;what is the device connected to this port -&amp;nbsp;&lt;SPAN&gt;interface GigabitEthernet0/8 ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 09:30:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724230#M901866</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-12T09:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: MAB &amp; Dot1x with NPS - new mac address is seen?</title>
      <link>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724516#M901867</link>
      <description>&lt;P&gt;All port have Cisco 6921 phones with Dell Pc's behind them.&lt;/P&gt;
&lt;P&gt;I think I may have found the culprit.......SCCM wake up proxy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was seeing mac addresses of different pc's switching to different ports even though those pc's were not physically doing it. So I started to think "mac flap" which finally lead me to this post:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/switching/mac-address-flapping-and-sccm-wake-up-proxy/td-p/2240432" target="_self"&gt;https://community.cisco.com/t5/switching/mac-address-flapping-and-sccm-wake-up-proxy/td-p/2240432&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So, into SCCM and disabled M$ version of wake on lan called "Wake up proxy" and since that, all appears ok.&lt;/P&gt;
&lt;P&gt;Early days yet but it's looking promising. Microsoft strikes again!!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 18:57:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724516#M901867</guid>
      <dc:creator>louis0001</dc:creator>
      <dc:date>2018-10-12T18:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: MAB &amp; Dot1x with NPS - new mac address is seen?</title>
      <link>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724553#M901869</link>
      <description>&lt;P&gt;Glad you found the issue, i was guessing some VM in the PC, like hyper-visor.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 19:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/mab-amp-dot1x-with-nps-new-mac-address-is-seen/m-p/3724553#M901869</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-12T19:57:20Z</dc:date>
    </item>
  </channel>
</rss>

